PT-2022-12181 · Wondershare · Wondershare Dr.Fone

Published

2022-04-29

·

Updated

2022-09-09

·

CVE-2021-44595

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Wondershare Dr. Fone version as of 2021-12-06
Description The issue allows a normal user to send manually crafted packets to the ElevationService.exe, enabling the execution of arbitrary code without validation and granting SYSTEM privileges.
Recommendations For Wondershare Dr. Fone version as of 2021-12-06, consider restricting access to the ElevationService.exe until a patch is available to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-44595

Affected Products

Wondershare Dr.Fone